Controls and awareness measures protecting against manipulation and deception attacks.
Social engineering defence combines technical controls, processes, and awareness to protect against manipulation attacks—phishing, pretexting, baiting, and impersonation. Technical controls include email filtering, multi-factor authentication, and verification procedures. Process controls include callback verification for payment changes and escalation procedures for unusual requests. Awareness training helps people recognise and resist manipulation attempts.
Why It Matters
The DSC Perspective:
Social engineering bypasses technical controls by targeting people. Layer technical protections, verification processes, and awareness training. Make it easy for staff to verify suspicious requests without feeling awkward.
